Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
quirogaca
New Contributor II

Please help - I do not understand how or where to check for logs

 

 

Hello Everyone:

 

On my Fortigate 60E, I do not understand how the traffic is logged. For example, I am seeing some peaks on the dashboard at certain hours, and I just cannot find the way to relate those peaks to any connection or device or IP, even though I see the sources and destinations list. Maybe there is some other screen and I cannot find it.

 

Can anybody please help, I am new to managing this brand of devices.

 

Thank you.

 

 

2 REPLIES 2
oheigl
Contributor II

In the FortiView > All Sessions you should be able to sort by the current throughput. The traffic logs only will not assist you in this case, because if there is for example a software, which always uses the same session and doesn't close it, you will not see it in the log till the connection is closed.

Maybe you can try to set up a netflow/sflow analyzer, I guess this would help

 

ux_guy_FTNT

Hi quirogaca,

Welcome & glad to have you using our products.

It is possible to select a timeframe within the widget, it will then prompt you to view either sources or destinations in FortiView.

Did this help you track down the reason for the spike?

 

 

Labels
Top Kudoed Authors